W32/Sober.K@mm
| W32/Sober.K@mm |
Destructivity: |
| • Detected by virus detection files published: 2/21/2005 | • Type: Worm |
| • Virus characteristics first published: 2/21/2005 | • Spreading mechanism: Email |
| • Virus characteristics latest update: 10/30/2007 | • Overall risk: Low |
| • Infection type: Microsoft Windows 95/98/98 SE/ME/NT 4/2000/XP/2003/Vista |
| Virus type |
Spreading mechanism |
Destructivity and payload |
Additional descriptions |
Detection and removal |
||||||||||
Email characteristics:
When the worm is executed, it will display a NOTEPAD window with a MIME-encoded text and an error message. In the background it now creates a number of files in the File system changes: In folder smss.exe The last 10 files are used for preliminary storage of harvested email addresses and MIME-encoded copies of the worm. In folder read.me The file read.me contains the following text: Ist eine weitere Test-Version. Läuft nur ein paar Tage! In diesem Sinne: Registry changes: Creates key HKLM\Software\Microsoft\Windows\CurrentVersion\Run winsystem.sys = Email generation: The worm harvest email addresses from local sources and sends mail itself to these with itself as an attachment (inside a ZIP file). The mail subject and body is variable, based on lists in the worm. If the recipient address is in Germany, Austria, Liechtenstein or Switzerland, the email text will be in German, otherwise it will be in English. The file attachment is a zip file containing a copy of the worm. The last extension of the file in the zip archive is attempted hidden by inserting spaces in the file name. Ex. : doc_data-text.txt |
||||||||||||||